Debian Ffmpeg vulnerabilities
375 known vulnerabilities affecting debian/ffmpeg.
Total CVEs
375
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL60HIGH117MEDIUM118LOW80
Vulnerabilities
Page 16 of 19
CVE-2025-22921P4MEDIUMCVSS 6.5fixed in ffmpeg 7:4.3.8-0+deb11u3 (bullseye)2025
CVE-2025-22921 [MEDIUM] CVE-2025-22921: ffmpeg - FFmpeg git-master,N-113007-g8d24a28d06 was discovered to contain a segmentation ...
FFmpeg git-master,N-113007-g8d24a28d06 was discovered to contain a segmentation violation via the component /libavcodec/jpeg2000dec.c.
Scope: local
bookworm: open
bullseye: resolved (fixed in 7:4.3.8-0+deb11u3)
forky: resolved (fixed in 7:8.0.1-2)
sid: resolved (fixed in 7:8.0.1-2)
trixie: open
debian
CVE-2009-4640P4MEDIUMCVSS 4.3fixed in ffmpeg 4:0.5+svn20090706-3 (bookworm)2009
CVE-2009-4640 [MEDIUM] CVE-2009-4640: ffmpeg - Array index error in vorbis_dec.c in FFmpeg 0.5 allows remote attackers to cause...
Array index error in vorbis_dec.c in FFmpeg 0.5 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Vorbis file that triggers an out-of-bounds read.
Scope: local
bookworm: resolved (fixed in 4:0.5+svn20090706-3)
bullseye: resolved (fixed in 4:0.5+svn20090706-3)
forky: resolved (fixed in 4:0.5+svn20090706-3)
sid: reso
debian
CVE-2018-6621P4LOWCVSS 6.5fixed in ffmpeg 7:3.4.2-1 (bookworm)2018
CVE-2018-6621 [MEDIUM] CVE-2018-6621: ffmpeg - The decode_frame function in libavcodec/utvideodec.c in FFmpeg through 3.2 allow...
The decode_frame function in libavcodec/utvideodec.c in FFmpeg through 3.2 allows remote attackers to cause a denial of service (out of array read) via a crafted AVI file.
Scope: local
bookworm: resolved (fixed in 7:3.4.2-1)
bullseye: resolved (fixed in 7:3.4.2-1)
forky: resolved (fixed in 7:3.4.2-1)
sid: resolved (fixed in 7:3.4.2-1)
trixie: resolved (fixed in 7:3.4
debian
CVE-2015-6761P4MEDIUMCVSS 6.8fixed in ffmpeg 7:2.8.1-1 (bookworm)2015
CVE-2015-6761 [MEDIUM] CVE-2015-6761: ffmpeg - The update_dimensions function in libavcodec/vp8.c in FFmpeg through 2.8.1, as u...
The update_dimensions function in libavcodec/vp8.c in FFmpeg through 2.8.1, as used in Google Chrome before 46.0.2490.71 and other products, relies on a coefficient-partition count during multi-threaded operation, which allows remote attackers to cause a denial of service (race condition and memory corruption) or possibly have unspecified other impact via a crafted W
debian
CVE-2020-22054P4LOWCVSS 6.5fixed in ffmpeg 7:4.3-2 (bookworm)2020
CVE-2020-22054 [MEDIUM] CVE-2020-22054: ffmpeg - A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in t...
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the av_dict_set function in dict.c.
Scope: local
bookworm: resolved (fixed in 7:4.3-2)
bullseye: resolved (fixed in 7:4.3-2)
forky: resolved (fixed in 7:4.3-2)
sid: resolved (fixed in 7:4.3-2)
trixie: resolved (fixed in 7:4.3-2)
debian
CVE-2020-22049P4LOWCVSS 6.5fixed in ffmpeg 7:4.3-2 (bookworm)2020
CVE-2020-22049 [MEDIUM] CVE-2020-22049: ffmpeg - A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in t...
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the wtvfile_open_sector function in wtvdec.c.
Scope: local
bookworm: resolved (fixed in 7:4.3-2)
bullseye: resolved (fixed in 7:4.3-2)
forky: resolved (fixed in 7:4.3-2)
sid: resolved (fixed in 7:4.3-2)
trixie: resolved (fixed in 7:4.3-2)
debian
CVE-2020-22019P4MEDIUMCVSS 6.5fixed in ffmpeg 7:4.3.2-0+deb11u2 (bookworm)2020
CVE-2020-22019 [MEDIUM] CVE-2020-22019: ffmpeg - Buffer Overflow vulnerability in FFmpeg 4.2 at convolution_y_10bit in libavfilte...
Buffer Overflow vulnerability in FFmpeg 4.2 at convolution_y_10bit in libavfilter/vf_vmafmotion.c, which could let a remote malicious user cause a Denial of Service.
Scope: local
bookworm: resolved (fixed in 7:4.3.2-0+deb11u2)
bullseye: resolved (fixed in 7:4.3.2-0+deb11u2)
forky: resolved (fixed in 7:4.3.2-0+deb11u2)
sid: resolved (fixed in 7:4.3.2-0+deb11u2)
trix
debian
CVE-2018-12459P4LOWCVSS 6.5fixed in ffmpeg 7:4.0.1-2 (bookworm)2018
CVE-2018-12459 [MEDIUM] CVE-2018-12459: ffmpeg - An inconsistent bits-per-sample value in the ff_mpeg4_decode_picture_header func...
An inconsistent bits-per-sample value in the ff_mpeg4_decode_picture_header function in libavcodec/mpeg4videodec.c in FFmpeg 4.0 may trigger an assertion violation while converting a crafted AVI file to MPEG4, leading to a denial of service.
Scope: local
bookworm: resolved (fixed in 7:4.0.1-2)
bullseye: resolved (fixed in 7:4.0.1-2)
forky: resolved (fixed in 7:4.0.
debian
CVE-2024-36613P4MEDIUMCVSS 6.2fixed in ffmpeg 7:5.1.5-0+deb12u1 (bookworm)2024
CVE-2024-36613 [MEDIUM] CVE-2024-36613: ffmpeg - FFmpeg n6.1.1 has a vulnerability in the DXA demuxer of the libavformat library ...
FFmpeg n6.1.1 has a vulnerability in the DXA demuxer of the libavformat library allowing for an integer overflow, potentially resulting in a denial-of-service (DoS) condition or other undefined behavior.
Scope: local
bookworm: resolved (fixed in 7:5.1.5-0+deb12u1)
bullseye: resolved (fixed in 7:4.3.7-0+deb11u1)
forky: resolved (fixed in 7:7.0.1-3)
sid: resolved (fi
debian
CVE-2016-7393P4MEDIUMCVSS 5.5fixed in ffmpeg 7:2.4-1 (bookworm)2016
CVE-2016-7393 [MEDIUM] CVE-2016-7393: ffmpeg - Stack-based buffer overflow in the aac_sync function in aac_parser.c in Libav be...
Stack-based buffer overflow in the aac_sync function in aac_parser.c in Libav before 11.5 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.
Scope: local
bookworm: resolved (fixed in 7:2.4-1)
bullseye: resolved (fixed in 7:2.4-1)
forky: resolved (fixed in 7:2.4-1)
sid: resolved (fixed in 7:2.4-1)
trixie: resolved (fixed in 7
debian
CVE-2009-4638P4MEDIUMCVSS 4.3fixed in ffmpeg 4:0.5+svn20090706-3 (bookworm)2009
CVE-2009-4638 [MEDIUM] CVE-2009-4638: ffmpeg - Integer overflow in FFmpeg 0.5 allows remote attackers to cause a denial of serv...
Integer overflow in FFmpeg 0.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors.
Scope: local
bookworm: resolved (fixed in 4:0.5+svn20090706-3)
bullseye: resolved (fixed in 4:0.5+svn20090706-3)
forky: resolved (fixed in 4:0.5+svn20090706-3)
sid: resolved (fixed in 4:0.5+svn20090706-3)
trixie: resolve
debian
CVE-2011-4579P4MEDIUMCVSS 4.3fixed in ffmpeg 7:2.4.1-1 (bookworm)2011
CVE-2011-4579 [MEDIUM] CVE-2011-4579: ffmpeg - The svq1_decode_frame function in the SVQ1 decoder (svq1dec.c) in libavcodec in ...
The svq1_decode_frame function in the SVQ1 decoder (svq1dec.c) in libavcodec in FFmpeg 0.5.x before 0.5.7, 0.6.x before 0.6.4, 0.7.x before 0.7.9, and 0.8.x before 0.8.8; and in Libav 0.5.x before 0.5.6, 0.6.x before 0.6.4, and 0.7.x before 0.7.3 allows remote attackers to cause a denial of service (memory corruption) via a crafted SVQ1 stream, related to "dimensions
debian
CVE-2024-55069P4LOWCVSS 5.3fixed in ffmpeg 7:7.1.1-1 (forky)2024
CVE-2024-55069 [MEDIUM] CVE-2024-55069: ffmpeg - ffmpeg 7.1 is vulnerable to Null Pointer Dereference in function iamf_read_heade...
ffmpeg 7.1 is vulnerable to Null Pointer Dereference in function iamf_read_header in /libavformat/iamfdec.c.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 7:7.1.1-1)
sid: resolved (fixed in 7:7.1.1-1)
trixie: resolved (fixed in 7:7.1.1-1)
debian
CVE-2018-6912P4LOWCVSS 6.5fixed in ffmpeg 7:4.0.1-2 (bookworm)2018
CVE-2018-6912 [MEDIUM] CVE-2018-6912: ffmpeg - The decode_plane function in libavcodec/utvideodec.c in FFmpeg through 3.4.2 all...
The decode_plane function in libavcodec/utvideodec.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (out of array read) via a crafted AVI file.
Scope: local
bookworm: resolved (fixed in 7:4.0.1-2)
bullseye: resolved (fixed in 7:4.0.1-2)
forky: resolved (fixed in 7:4.0.1-2)
sid: resolved (fixed in 7:4.0.1-2)
trixie: resolved (fixed in 7:4
debian
CVE-2020-22051P4LOWCVSS 6.5fixed in ffmpeg 7:4.3-2 (bookworm)2020
CVE-2020-22051 [MEDIUM] CVE-2020-22051: ffmpeg - A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in t...
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the filter_frame function in vf_tile.c.
Scope: local
bookworm: resolved (fixed in 7:4.3-2)
bullseye: resolved (fixed in 7:4.3-2)
forky: resolved (fixed in 7:4.3-2)
sid: resolved (fixed in 7:4.3-2)
trixie: resolved (fixed in 7:4.3-2)
debian
CVE-2020-22044P4LOWCVSS 6.5fixed in ffmpeg 7:4.3-2 (bookworm)2020
CVE-2020-22044 [MEDIUM] CVE-2020-22044: ffmpeg - A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in t...
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the url_open_dyn_buf_internal function in libavformat/aviobuf.c.
Scope: local
bookworm: resolved (fixed in 7:4.3-2)
bullseye: resolved (fixed in 7:4.3-2)
forky: resolved (fixed in 7:4.3-2)
sid: resolved (fixed in 7:4.3-2)
trixie: resolved (fixed in 7:4.3-2)
debian
CVE-2020-22043P4LOWCVSS 6.5fixed in ffmpeg 7:4.3-2 (bookworm)2020
CVE-2020-22043 [MEDIUM] CVE-2020-22043: ffmpeg - A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak at t...
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak at the fifo_alloc_common function in libavutil/fifo.c.
Scope: local
bookworm: resolved (fixed in 7:4.3-2)
bullseye: resolved (fixed in 7:4.3-2)
forky: resolved (fixed in 7:4.3-2)
sid: resolved (fixed in 7:4.3-2)
trixie: resolved (fixed in 7:4.3-2)
debian
CVE-2020-22039P4LOWCVSS 6.5fixed in ffmpeg 7:4.3-2 (bookworm)2020
CVE-2020-22039 [MEDIUM] CVE-2020-22039: ffmpeg - A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in t...
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the inavi_add_ientry function.
Scope: local
bookworm: resolved (fixed in 7:4.3-2)
bullseye: resolved (fixed in 7:4.3-2)
forky: resolved (fixed in 7:4.3-2)
sid: resolved (fixed in 7:4.3-2)
trixie: resolved (fixed in 7:4.3-2)
debian
CVE-2020-22040P4LOWCVSS 6.5fixed in ffmpeg 7:4.3-2 (bookworm)2020
CVE-2020-22040 [MEDIUM] CVE-2020-22040: ffmpeg - A Denial of Service vulnerability exists in FFmpeg 4.2 idue to a memory leak in ...
A Denial of Service vulnerability exists in FFmpeg 4.2 idue to a memory leak in the v_frame_alloc function in frame.c.
Scope: local
bookworm: resolved (fixed in 7:4.3-2)
bullseye: resolved (fixed in 7:4.3-2)
forky: resolved (fixed in 7:4.3-2)
sid: resolved (fixed in 7:4.3-2)
trixie: resolved (fixed in 7:4.3-2)
debian
CVE-2020-22046P4LOWCVSS 6.5fixed in ffmpeg 7:4.3-2 (bookworm)2020
CVE-2020-22046 [MEDIUM] CVE-2020-22046: ffmpeg - A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in t...
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the avpriv_float_dsp_allocl function in libavutil/float_dsp.c.
Scope: local
bookworm: resolved (fixed in 7:4.3-2)
bullseye: resolved (fixed in 7:4.3-2)
forky: resolved (fixed in 7:4.3-2)
sid: resolved (fixed in 7:4.3-2)
trixie: resolved (fixed in 7:4.3-2)
debian